Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows ImageLoad: Uncommon Process Loads RstrtMgr.dll (Restart Manager)
Alerts on non-standard processes loading RstrtMgr.dll using Windows image load telemetry.
Luc Génaux, Huntrule TeamWindowsimage_loadLow141Free2023-11-28Windows Image Load of RstrtMgr.dll by Suspicious Path or User Content
Alerts on RstrtMgr.dll loading from suspicious path contexts using Windows image load telemetry.
Luc Génaux, Huntrule TeamWindowsimage_loadHigh122Free2023-11-28Detect CVE-2023-4966 Citrix ADC Sensitive Info Disclosure Attempts in Webserver Logs via Long Host Header
Alerts on GET requests to the OpenID configuration endpoint with an unusually long Host header, indicative of CVE-2023-4966 probing.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh206Free2023-11-28CVE-2023-4966 Sensitive Info Disclosure Attempt on Citrix ADC via Webserver Logs
Alerts on successful GET requests to the OIDC openid-configuration path that match CVE-2023-4966 related probing patterns.
Nasreddine Bencherchali (Nextron Systems), Michael Haag (STRT), Huntrule Team—webserverMedium394Free2023-11-28Citrix ADC Proxy Log Detection for CVE-2023-4966 Sensitive Info Disclosure Attempts via OIDC Endpoint
Alerts on successful GETs to /oauth/idp/.well-known/openid-configuration in Citrix ADC proxy logs consistent with CVE-2023-4966 probing.
Nasreddine Bencherchali (Nextron Systems), Michael Haag (STRT), Huntrule Team—proxyMedium189Free2023-11-28Citrix ADC CVE-2023-4966 Proxy Exploitation Attempt via Oversized Host Header (GET /oauth idp well-known)
Flags proxy GETs to the OpenID configuration endpoint with an excessively long Host header consistent with CVE-2023-4966 probing.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyHigh92Free2023-11-28Python-Based Tool LSASS Process Access for Credential Dumping (Windows)
Alerts on process-access attempts to lsass.exe with a Python-related call trace and high granted access.
Bhabesh Raj, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_accessHigh2210Free2023-11-27Windows HackTool Process Access: Detect Access by Common Tool Image Names
Alerts on Windows process access events initiated by processes whose image names match common credential/dumping hack tools.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_accessHigh344Free2023-11-27Splunk Enterprise RCE Exploitation Attempt via XML Upload and Search Job Requests
Flags Splunk web exploitation patterns for CVE-2023-46214 using shell.xsl uploads followed by search-result URIs.
Lars B. P. Frydenskov(Trifork Security), Huntrule Team—webserverHigh155Free2023-11-27Potential CVE-2023-46214 RCE Attempt via Insecure XML in Splunk Enterprise (Webserver HTTP POST)
Alerts on POST web requests to .xsl endpoints with NO_BINARY_CHECK=1 and input.path, returning 200/302—consistent with a CVE-2023-46214 probe.
Nasreddine Bencherchali (Nextron Systems), Bhavin Patel (STRT), Huntrule Team—webserverMedium314Free2023-11-27wusa.exe Execution with Parent in Suspicious Windows Paths
Alerts when wusa.exe is spawned by a parent running from common suspicious Windows directories, excluding .msu-related noise.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh422Free2023-11-26Windows Elevated Shell Spawn via Process Creation (PowerShell or CMD)
Flags creation of privileged PowerShell or cmd.exe processes tied to an elevated logon context.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium50Free2023-11-23Windows Registry IME File Value Used from Suspicious Paths
Alerts on Windows keyboard layout "Ime File" registry entries pointing to suspicious writable directory paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsregistry_setHigh60Free2023-11-21Windows Registry: Uncommon IME File Value in Keyboard Layouts Path
Alerts on Control\Keyboard Layouts\ registry values named "Ime File" that reference non-.ime extensions.
X__Junior (Nextron Systems), Huntrule TeamWindowsregistry_setHigh218Free2023-11-21Windows Network Connections to Visual Studio Code Tunnels Domain
Alerts on initiated network connections to .tunnels.api.visualstudio.com from a Windows process.
Kamran Saifullah, Huntrule TeamWindowsnetwork_connectionMedium112Free2023-11-20